Malware-Resistant Memory Capture via NVDIMM Mirroring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional malware detection systems are ineffective against advanced malware, such as rootkits, which can hide by altering OS functions and intercepting communications, and existing forensic analysis methods using DMA are vulnerable to compromise.
Innovation Solution
A malware-resistant memory capture system utilizing non-volatile Dual In-line Memory Modules (NVDIMMs) with backup memory and a memory controller that mirrors data between primary and secondary storage, allowing for secure data copying and analysis without requiring complex decoupling or recoupling of memory units, enabling continuous operation and immune to malware interference.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional DMA-based forensic analysis is used, then memory capture capability is provided, but the system becomes vulnerable to malware interference and compromise
Solution Approach 1:
The system divides memory into multiple independent banks (first memory bank, second memory bank) that operate independently. The processor can access one bank while forensic analysis occurs on another bank, isolating the analysis process from malware that may be present in the active memory bank.
Solution Approach 2:
A memory interface acts as an intermediary component between the processor/memory banks and the forensic analysis system. This intermediary enables secure data extraction and DMA-based analysis without requiring direct access to the processor or operating system, preventing malware from interfering with the analysis process.
2Reliability
If memory decoupling and recoupling is performed for forensic analysis, then memory capture is achieved, but system operation is disrupted
Solution Approach 1:
The memory system is segmented into multiple independent banks, allowing forensic analysis to be performed on one bank without affecting the operation of other banks. This eliminates the need to decouple or recouple memory units, as the analysis can proceed in parallel on a separate memory bank.
Solution Approach 2:
The system enables continuous operation by allowing the processor to continue accessing the first memory bank while forensic analysis simultaneously occurs on the second memory bank. This maintains uninterrupted system operation while achieving the forensic analysis objective.
3Reliability
If complex decoupling/recoupling procedures are implemented, then forensic analysis capability is improved, but device complexity increases
Solution Approach 1:
The memory system is divided into multiple independent banks with dedicated controllers, eliminating the need for complex decoupling/recoupling procedures. Each bank can be independently managed and analyzed, simplifying the overall control architecture.
Solution Approach 2:
A memory interface serves as an intermediary that simplifies the control architecture by providing a standardized interface for forensic analysis. This intermediary handles the complexity of data extraction and DMA operations, eliminating the need for complex memory decoupling procedures while maintaining forensic analysis capability.
Data Source
AI summary
There is provided a computer system of malware-resistant memory capture, comprising memory units operably connected to a first processor; secondary-storage-enabled memory units (SSEMUs) comprising a backup memory, being adapted to copy stored data to the comprised backup memory, and providing a data interface of reading from the backup memory; wherein the first processor and the one or more SSEMUs are configurable so that each SSEMU of the one or more SSEMUs at least partially mirrors a respective memory unit of the one or more memory units; and a memory controller (MC) operably connected to a control interface and the provided data interface of at least one SSEMU, and configured to signal, to the SSEMU, a control interface signal of copying of stored data to a comprised backup memory, and initiate reading of data from the comprised backup memory.


